Network Security Segment Negotiation via Device Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network management systems face inefficiencies and security risks due to reliance on conventional network devices making decisions about network segment associations without full awareness of all network activities, leading to potential security breaches and manual labor-intensive configurations.
Innovation Solution
A method where network devices obtain security update information from communication devices to determine the appropriate security segment based on changes in their profiles, reducing the risk of security breaches and improving network security by actively involving communication devices in segment association decisions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional network devices make decisions about network segment associations entirely on their own, then network management is simplified, but network security is compromised due to lack of awareness of all network activities
Solution Approach 1:
The patent implements a feedback mechanism where communication devices provide security update information to network devices. This allows network devices to make informed segmentation decisions based on real-time security status changes, resolving the contradiction by maintaining simplified management while improving security awareness through device feedback
Solution Approach 2:
Communication devices autonomously generate and transmit security update information when their security profiles change. This self-service approach enables network devices to receive accurate security data without manual intervention, enhancing security while keeping management automated
2Extent of automation
If network devices assign security segments without communication device input, then configuration is automated, but segment mismatches occur leading to security risks
Solution Approach 1:
The system uses feedback from communication devices about their security profile changes to improve segmentation accuracy. Devices report when their security status changes, allowing network devices to reassign segments appropriately, maintaining automation while reducing mismatches
Solution Approach 2:
The patent implements dynamic segment assignment where security segments are not fixed but can be reassigned based on changing security profiles. This dynamic approach allows automated configuration to adapt to new security conditions, improving assignment accuracy without reducing automation
3Adaptability or versatility
If communication devices use alternate networks bypassing regular channels, then communication flexibility is improved, but network device awareness is reduced creating security gaps
Solution Approach 1:
The patent establishes a feedback channel where communication devices transmit security update information directly to network devices even when using alternate networks. This ensures network devices remain aware of security-relevant activities regardless of the communication path used, maintaining flexibility while preventing information loss
Data Source
AI summary
A method for executing a security negotiation for a network configuration at a network device, includes obtaining, by the network device, a security update information from a communication device being assigned to a first security segment. The first security segment is associated with a first segment security profile. The security update information is indicative of at least one change in a first security profile of the communication device. The method further includes determining, by the network device, a second security segment for the communication device based on the security update information. An instruction is provided by the network device to the communication device to join the determined second security segment.


